Security Operations Center: Building, Operating, and Maintaining your SOC by Joseph Muniz & Gary McIntyre & Nadhem AlFardan
Author:Joseph Muniz & Gary McIntyre & Nadhem AlFardan [Muniz, Joseph]
Language: eng
Format: epub
Publisher: Pearson Education
Published: 2015-11-01T20:00:00+00:00
The Upper and Lower Bounds of Technology
Outside of the impact of process, another unforeseen challenge for the SOC team is associated with the technologies that could underpin SOC services. For example, security information and event management (SIEM) technologies tend to be limited in ways that impact the perceived effectiveness of the SOC. On the lower bound, the SIEM may either not see certain events from key systems or be unable to provide a long-term view into such data. On the upper bound, the SIEM may simply not alert the team to real security incidents because it either misinterprets event data or has been configured to ignore some events in favor of others. The SIEM might not have sufficient information about assets or the environment it is monitoring to distinguish serious attacks. In some organizations, the SOC may have little control over the technologies they rely on, and have less ability to influence improvement. Not having the right tools can be frustrating for the SOC team and could lead to a failure for which the team will be held responsible.
Download
This site does not store any files on its server. We only index and link to content provided by other sites. Please contact the content providers to delete copyright contents if any and email us, we'll remove relevant links or contents immediately.
Sass and Compass in Action by Wynn Netherland Nathan Weizenbaum Chris Eppstein Brandon Mathis(7787)
Grails in Action by Glen Smith Peter Ledbrook(7704)
Configuring Windows Server Hybrid Advanced Services Exam Ref AZ-801 by Chris Gill(6613)
Azure Containers Explained by Wesley Haakman & Richard Hooper(6601)
Running Windows Containers on AWS by Marcio Morales(6129)
Kotlin in Action by Dmitry Jemerov(5073)
Microsoft 365 Identity and Services Exam Guide MS-100 by Aaron Guilmette(4941)
Combating Crime on the Dark Web by Nearchos Nearchou(4522)
Management Strategies for the Cloud Revolution: How Cloud Computing Is Transforming Business and Why You Can't Afford to Be Left Behind by Charles Babcock(4421)
Microsoft Cybersecurity Architect Exam Ref SC-100 by Dwayne Natwick(4381)
The Ruby Workshop by Akshat Paul Peter Philips Dániel Szabó and Cheyne Wallace(4192)
The Age of Surveillance Capitalism by Shoshana Zuboff(3961)
Python for Security and Networking - Third Edition by José Manuel Ortega(3764)
Learn Windows PowerShell in a Month of Lunches by Don Jones(3513)
The Ultimate Docker Container Book by Schenker Gabriel N.;(3429)
Mastering Python for Networking and Security by José Manuel Ortega(3348)
Mastering Azure Security by Mustafa Toroman and Tom Janetscheck(3337)
Blockchain Basics by Daniel Drescher(3305)
Learn Wireshark by Lisa Bock(3305)
